8.1

CVSS3.1

CVE-2025-3909 - JavaScript Execution via Spoofed PDF Attachment and file:/// Link

Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested email attachment (message/rfc822) and setting its content type to application/pdf, Thunderbird may incorrectly render it as HTML when opened, a…

πŸ“… Published: May 14, 2025, 4:56 p.m. πŸ”„ Last Modified: April 13, 2026, 2:27 p.m.

7.5

CVSS3.1

CVE-2025-3875 - Sender Spoofing via Malformed From Header in Thunderbird

Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address to be used. For example, if the From header contains an (invalid) value "Spoofed Name ", Thunderbird treats [email protected] as the actual address. This vulnerability was fixed…

πŸ“… Published: May 14, 2025, 4:56 p.m. πŸ”„ Last Modified: April 13, 2026, 2:27 p.m.

7.2

CVSS3.1

CVE-2025-40595 -

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. By using an encoded URL, a remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

πŸ“… Published: May 14, 2025, 4:35 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.9

CVSS4.0

CVE-2025-47782 - motionEye vulnerable to RCE in add_camera Function Due to unsafe command execution

motionEye is an online interface for the software motion, a video surveillance program with motion detection. In versions 0.43.1b1 through 0.43.1b3, using a constructed (camera) device path with the `add`/`add_camera` motionEye web API allows an attacker with motionEye admin user credentials to exe…

πŸ“… Published: May 14, 2025, 3:54 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-47781 - Rallly Insufficient Password Login Token Entropy Leads to Account Takeover

Rallly is an open-source scheduling and collaboration tool. Versions up to and including 3.22.1 of the application features token based authentication. When a user attempts to login to the application, they insert their email and a 6 digit code is sent to their email address to complete the authent…

πŸ“… Published: May 14, 2025, 3:52 p.m. πŸ”„ Last Modified: Nov. 6, 2025, 10:04 p.m.

6.1

CVSS4.0

CVE-2025-47778 - Sulu vulnerable to XXE in SVG File upload Inspector

Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5, and 3.0.0-alpha1, an admin user can upload SVG which may load external data via XML DOM library. This can be used for insecure XML External Entity References. The problem has bee…

πŸ“… Published: May 14, 2025, 3:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.7

CVSS3.1

CVE-2025-47777 - 5ire Client Vulnerable to Cross-Site Scripting (XSS) and Remote Code Execution (RCE)

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Versions prior to 0.11.1 are vulnerable to stored cross-site scripting in chatbot responses due to insufficient sanitization. This, in turn, can lead to Remote Code Execution (RCE) via unsafe Elect…

πŸ“… Published: May 14, 2025, 3:23 p.m. πŸ”„ Last Modified: Jan. 22, 2026, 9:26 p.m.

6.2

CVSS3.1

CVE-2025-47775 - Bullfrog's DNS over TCP bypasses domain filtering

Bullfrog is a GithHb Action to block unauthorized outbound traffic in GitHub workflows. Prior to version 0.8.4, using tcp breaks blocking and allows DNS exfiltration. This can result in sandbox bypass. Version 0.8.4 fixes the issue.

πŸ“… Published: May 14, 2025, 3:18 p.m. πŸ”„ Last Modified: July 11, 2025, 4:15 p.m.

5

CVSS3.1

CVE-2025-24969 - iTop portal user can see any other contact's picture

iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts picture by changing the picture ID in the URL. Version 3.2.1 contains a patch for the issue.

πŸ“… Published: May 14, 2025, 3:11 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 8:49 p.m.

4.3

CVSS3.1

CVE-2025-24785 - iTop dashboard vulnerable to denial of service

iTop is an web based IT Service Management tool. In version 3.2.0, an attacker may send a URL to the server to trigger a PHP error. The next user trying to load this dashboard would encounter a crashed start page. Version 3.2.1 fixes the issue by checking the provided layout_class before saving the…

πŸ“… Published: May 14, 2025, 3:05 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 6:38 p.m.
Total resulsts: 344690
Page 4964 of 34,469
Β« previous page Β» next page
Filters